DPDP security obligations: what Rule 6 asks you to build by May 2027
The DPDP security safeguards and breach-intimation duties commence 13 May 2027, not today. What Rule 6 requires at minimum, the two breach clocks under Rule 7, and what has to exist before then.
Most writing about the DPDP Rules describes obligations that are not yet in force, without saying so. The security safeguards and the breach-intimation duties both commence eighteen months after publication — on 13 May 2027. That is not a reason to ignore them. It is the reason the useful question today is what has to exist by then, because Rule 6 describes an operating capability rather than a document.
What is in force, and what is not yet
The Rules were notified as G.S.R. 846(E) on 13 November 2025 and commence in three tranches, set out in Rule 1 itself. The Act's own provisions were commenced the same day on a matching schedule.
| From | Rules | What it covers |
|---|---|---|
| 13 November 2025 | 1, 2 and 17 to 21 | Definitions, and the machinery of the Data Protection Board — its functioning as a digital office, and the terms of service of its chairperson and members |
| 13 November 2026 | 4 | Registration and obligations of Consent Managers |
| 13 May 2027 | 3, 5 to 16, 22 and 23 | Notice, reasonable security safeguards, breach intimation, retention limits, Data Principal rights, Significant Data Fiduciary obligations, and transfers outside India |
Rule 6: the seven minimum safeguards
Rule 6 requires a Data Fiduciary to protect personal data in its possession or under its control — including data processed on its behalf by a Data Processor — by taking reasonable security safeguards to prevent a personal data breach. Seven are named as the minimum:
- (a) Data security measures. Securing personal data through encryption, obfuscation, masking, or virtual tokens mapped to that data. The rule names the techniques rather than leaving "appropriate" undefined.
- (b) Access control. Appropriate measures to control access to the computer resources used by the Data Fiduciary or its Data Processor.
- (c) Visibility through logs. Logs, monitoring and review sufficient to detect unauthorised access, investigate it, and remediate to prevent recurrence.
- (d) Continuity. Reasonable measures for continued processing where confidentiality, integrity or availability is compromised — data backups are the example the rule gives.
- (e) One year of retention. Logs and personal data retained for one year, unless another law in force requires otherwise, so that detection, investigation and remediation are actually possible after the fact.
- (f) Processor contracts. Appropriate provision in the contract with any Data Processor requiring it to take reasonable security safeguards.
- (g) Technical and organisational measures. Measures sufficient to ensure the safeguards are effectively observed, rather than merely adopted.
Two features of that list are worth reading carefully. It is a floor, not a ceiling — “at the minimum” is the rule's own phrase, so meeting all seven is the start of the argument rather than the end of it. And clause (a) departs from the usual drafting by naming techniques: encryption, obfuscation, masking and tokenisation are specified, which makes their absence harder to characterise as a reasonable judgement call.
Clause (f) is the one that reaches outside the organisation. Security obligations have to be written into Data Processor contracts, and the Data Fiduciary remains responsible for data processed on its behalf. That is the same principle the RBI and SEBI apply to outsourcing — liability does not travel with the contract — arriving now for every organisation that handles personal data, regulated or not.
Rule 7: two clocks, and neither of them is six hours
On becoming aware of a personal data breach, a Data Fiduciary owes intimations in two directions, on different timetables.
To each affected Data Principal — without delay
In concise, clear and plain language, through her user account or a mode of communication she has registered: a description of the breach including its nature, extent and timing; the consequences likely to arise for her; the mitigation measures implemented and being implemented; the safety measures she can take herself; and business contact information for someone who can answer her questions.
There is no threshold in the rule. It is not limited to breaches above a size, a sensitivity or a likelihood of harm.
To the Data Protection Board — without delay, then 72 hours
First, without delay, a description of the breach: nature, extent, timing, location and likely impact. Then within seventy-two hours of becoming aware — or a longer period the Board allows on a written request — the fuller account: updated detail, the broad facts and circumstances leading to the breach, mitigation measures implemented or proposed, any findings about who caused it, remedial measures to prevent recurrence, and a report on the intimations given to affected Data Principals.
If you are a Significant Data Fiduciary
Rule 13 adds obligations for Data Fiduciaries notified as significant, or included in a class notified as such. Once in every period of twelve months, an SDF must undertake a Data Protection Impact Assessment and an audit, and must cause the person carrying them out to furnish the Board with a report of significant observations.
Two further duties are less discussed. An SDF must observe due diligence to verify that the technical measures it uses — including algorithmic software — for hosting, display, upload, modification, publication, transmission, storage, updating or sharing of personal data are not likely to pose a risk to the rights of Data Principals. And it must ensure that personal data specified by the Central Government, along with the traffic data pertaining to its flow, is not transferred outside India.
What has to exist by May 2027
Read as a build list rather than a compliance checklist, Rule 6 asks for capabilities that take longer to establish than the drafting suggests.
- Know where personal data is. Every clause of Rule 6 is scoped to personal data in your possession or control. An organisation that cannot enumerate where that data sits cannot demonstrate any of the seven safeguards over it.
- Logging that survives a year. Clause (e) sets one year for logs and personal data. Retention is a storage and cost decision with a lead time, not a configuration change made the week before a deadline.
- A breach process that can start inside hours. The Board's seventy-two hours is generous next to CERT-In's six, but the initial intimation to both the Board and affected Data Principals is due “without delay”, and the same detection has to trigger all of them.
- Processor contracts reopened. Clause (f) requires security provisions in Data Processor contracts. Renegotiating a supplier estate takes quarters, and it is the item most likely to be left until it cannot be finished.
- A named contact who answers. Rule 7 requires business contact information for a person who can respond to a Data Principal's queries — published, staffed and current before it is needed.
Where BitScore fits, and where it does not
A security rating is not DPDP compliance and cannot be presented as it. Rule 6 is about personal data inside your systems — encryption, access control, retention, processor contracts — and an externally calculated rating sees none of that. Nothing on this site should be read as suggesting otherwise.
The overlap is narrower and worth stating exactly. Rule 6(c) requires visibility sufficient to detect unauthorised access, and Rule 7's clocks all start on becoming aware. Continuous external observation of your internet-facing estate is one input to becoming aware, and it is evidence a third party produced rather than an assertion you made. It also reaches your Data Processors, which clause (f) makes your problem contractually and which you have no other independent view of.
Read next
- CERT-In's six-hour rule — the reporting obligation that is in force today and covers the same organisations.
- Cyber security regulations in India — every instrument, and which sector regulator applies on top of this.
- Third-party risk management for Indian BFSI — the processor-contract problem, from the vendor-risk side.
Rule numbers, commencement dates and the text of Rules 6, 7 and 13 read from G.S.R. 846(E), the Digital Personal Data Protection Rules, 2025 as published in the Gazette on 13 November 2025, and the Act's commencement schedule from G.S.R. 843(E) of the same date. Every instrument cited here was verified against the issuing regulator's own notification on . This page is general information, not legal advice — confirm applicability and current status with your own counsel and compliance function.
Questions this page answers
- Are the DPDP security obligations in force now?
- Not yet. The Rules were notified on 13 November 2025, but Rule 6 on security safeguards and Rule 7 on breach intimation fall in the tranche commencing eighteen months later, on 13 May 2027. Only the definitions and the Data Protection Board machinery took effect on notification; Consent Manager registration follows on 13 November 2026.
- What counts as reasonable security safeguards under DPDP?
- Rule 6 names seven as the minimum: encryption, obfuscation, masking or tokenisation; access control; logs and monitoring sufficient to detect unauthorised access; backups for continued processing; one year of log and data retention; security provisions in Data Processor contracts; and technical and organisational measures ensuring the safeguards are observed rather than merely adopted.
- How quickly must a personal data breach be reported under DPDP?
- Affected Data Principals must be intimated without delay, with no threshold for size or severity. The Data Protection Board gets an initial description without delay, then a full report within seventy-two hours of the Data Fiduciary becoming aware — extendable only on a written request the Board allows.
- Does DPDP breach reporting replace the CERT-In six-hour rule?
- No. The CERT-In Directions have required reporting within six hours since 2022 and are in force today. From May 2027 the same incident can start the CERT-In six-hour clock, the DPDP intimation to Data Principals, the seventy-two-hour report to the Board, and a sector regulator’s own clock. None discharges another.
- What extra applies to a Significant Data Fiduciary?
- Rule 13 requires a Data Protection Impact Assessment and an audit once every twelve months, with significant observations reported to the Board. A Significant Data Fiduciary must also verify that its technical measures, including algorithmic software, do not risk Data Principals’ rights, and must keep government-specified personal data and its traffic data inside India.